1.6 Migration via new Install with no DB Transfer
-
I just did a massive overhaul on our fog service, migrating directly into 1.6 by running a new server from scratch rather than a database migration (there were some Foreign Key check failures on the in-place upgrade), and for the most part everything seems to be working except reliable agent communication. Both on the old and new agent I’m having a bitch of a time with the CA communication.
When using the new agent from the GitHub, I get a 503 error, so referencing the apache error logs gives me a bit of insight:
Got error 'PHP message: FOG agent enroll: signing for host 387 from 10.1.60.40 failed: the issued certificate does not verify against /opt/fog/snapins/ssl/CA/.fogCA.pem'In this instance, this was a fresh agent install, so I’m not sure what cert is being compared to what. I’m assuming until told otherwise that my FOG Generated PKI is foobar for production use, but I’m unsure of the steps to even take in this instance.
-
@Coolguy3289 Thanks for the log line. It points at a bug, not at your approach.
The installer creates a “FOG Agent CA” under the server root CA. It only creates it when the file is missing. If the root CA changes later (for example, you copy the old server’s
/opt/fog/snapins/sslonto the new box so existing clients keep trusting it), the agent CA stays signed by the first root. Every enrollment then fails with the error you see, and the agent gets a 503.The fix is in PR #1810: the installer now re-creates the agent CA when the current root did not sign it.
To fix your server now, without waiting for the PR:
sudo grep PKI_AGENT_CA_CERT /opt/fog/.fog-pkiMove the
.fogAgentCA.pemand.fogAgentCA.keyfiles in that directory to a backup location. Then re-run the installer. It creates a new agent CA under your current root, and enrollment works.You do not need your internal PKI for this. The FOG-generated root is fine for production.